When the NHI card component becomes an backdoor for hackers

中文In-PersonVulnerability Analysis

Three vulnerabilities were found in the Taiwan National Health Insurance (NHI) card involving Race Condition, Stack Overflow, and Heap Overflow.

NHI cards need to interact with card readers for authentication. As browsers do not support such functionality, the local device will utilize Web Services for authentication. Security surrounding the Web Service implementation then becomes particularly critical as poor practices pose a severe threat to the local device as well as the NHI card itself.

In 2022, these three vulnerabilities pose an even greater threat to Taiwan as the widespread use of the NHI card has only increased due to the pandemic. Vaccine registration systems needed to rely on NHI cards for authentication.

In this presentation, we will discuss how the NHI’s architecture allowed these vulnerabilities to happen, how these potential threats were detected, take you step-by-step through our in-depth analysis, and show how a heap overflow led to successfully achieving RCE in Linux.

Since our discovery, we have since been in contact with manufacturers and have collaborated on patching these particular vulnerabilities to reduce further risk to users.

Yu-Hsiang Lin

Yu-Hsiang Lin

Yu-Hsiang Lin (林宇翔), a recent addition to the CyCraft Intern Program, is currently studying at National Yang Ming Chiao Tung University’s Department of Computer Science. He is a member of the TSJ CTF team, BambooFox, and has lectured at SITCON for the Ministry of Education’s Information Security Incubation Program (ISIP).

English interpretations will be provided for all sessions not presented in English.

Agenda Table

Use event local timezone
TimeZone

00:30

  • Attendant Registration Time

01:20

  • Welcome Speech & Event Introduce

02:10

03:00

  • Break

03:15

04:05

  • Lunch

05:00

05:45

  • Break

06:00

06:45

  • Tea Time

07:00

07:25

08:10

  • Break

08:25

09:10

  • Closing

09:25